PAGE 07 / JOURNAL — ENTRY OF RECORD 2026
Four in five Australian firms' privacy policies say nothing about AI
We read 284 accounting, legal and financial-services privacy policies. 81% don't mention AI at all, 98 days before the ADM transparency rule. What the few that do say, and why the gap is usually governance, not law.
Somebody in your firm used generative AI on a client matter this week. The question is whether your privacy policy, the one public document that is supposed to describe how you handle personal information, says anything about it.
For most Australian professional-services firms, it doesn't. We read the privacy policies of 284 accounting, legal and financial-services firms on 3 September 2026. 81% make no reference to artificial intelligence, machine learning or automated decision-making. Not a sentence.
Read the full study, method and named appendix →
The numbers that matter
- 23 firms (8%) publish a specific disclosure: what AI is used for, and at least one safeguard.
- 26 firms (9%) mention automated decision-making or profiling, the exact subject of the Privacy Act obligation that commences on 10 December 2026.
- Accounting disclose least. 13% of accounting policies mention AI, against 21% of law firms and 23% of financial-services firms.
- Recency is the strongest signal. Policies dated 2025 or later mention AI 39% of the time. Policies dated 2024 or earlier: 8%. Half of all policies carry no date at all.
This is not a compliance finding
Say it plainly, because it will be misread otherwise: a policy that says nothing about AI has not thereby done anything wrong. The ADM transparency obligation is not yet in force, it applies only to automated decisions that could affect someone's rights or interests, and a silent public policy can sit above an excellent internal one.
What the study measures is public disclosure: what a client, a regulator or a journalist can read today. The regulator's own words on what changes in December:
From 10 December 2026, APP entities that use personal information in ADM with the potential to affect rights or interests will be required to provide information in their privacy policies about the kinds of personal information used and the kinds of decisions made using ADM.— OAIC — Consultation on guidance for transparency in automated decision making, quoted verbatim 2026-09-08
That is 98 days from the snapshot. From December, a firm that uses personal information in automated decisions that could affect someone's rights or interests, such as risk scoring, intake triage or credit assessment, will need its privacy policy to say so, and to say what kinds of decisions are involved.
What the good ones say
The 23 specific disclosures cluster tightly. Four uses: meeting transcription (Microsoft Copilot is named most often), document review and research, drafting and summarising, intake chatbots and risk scoring. Three safeguards: a human reviews before anyone relies on the output, client data is not used to train models, and the tools come from an approved list in an enterprise environment.
None of that is exotic. It is a paragraph. The firms that have it mostly touched their policy since the start of last year; the firms that don't, didn't. Which points at the real finding.
The gap is governance, not drafting
A privacy policy that mentions AI is the visible end of a chain: someone decided which tools are allowed, someone decided what they may be used for, someone wrote the rule down, and then someone told the public. Firms missing the last link are usually missing the first three.
That is what the organisational AI readiness audit measures, department by department, in about five minutes. If your policy is one of the 81%, start there.
The full report publishes the method in full, every table, and a named appendix of the 23 firms whose policies do the job well. No firm is named for scoring poorly.